🇪🇺 Cloud Sovereignty Framework — Provider Cards

← Ranking

DigitalOcean

United States · IaaS/PaaS · https://www.digitalocean.com

Sovereignty score32.0%
Global (unweighted)33.0%
Overall SEAL
SEAL-1 Jurisdictional Sovereignty
SOV-1 Strategic Sovereignty23.0SEAL-1
SOV-2 Legal & Jurisdictional Sovereignty21.0SEAL-1
SOV-3 Data & AI Sovereignty45.0SEAL-1
SOV-4 Operational Sovereignty25.1SEAL-1
SOV-5 Supply Chain Sovereignty21.6SEAL-1
SOV-6 Technology Sovereignty45.0SEAL-2
SOV-7 Security & Compliance Sovereignty39.6SEAL-1
SOV-8 Environmental Sustainability43.8SEAL-1

SOV-1 · Strategic Sovereignty 23.0% · SEAL-1 · weight 20%

IDFactorValueScoreSEALConf.Justification
SOV-1.1EU/EEA legal entity control1. Entirely outside the EU0/125SEAL-1highforeign_parent (DigitalOcean Holdings, Inc., Delaware/NYSE:DOCN, US HQ); controlling entity entirely outside the EU -> SOV-1.1 opt1. (src: https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001582961&type=10-K)
SOV-1.2Change of control risk4. Unlikely takeover/transfer to non-EU sovereign entity94/125SEAL-4mediumPublicly traded (NYSE:DOCN) and acquirable, but no announced takeover; control distributed among (mostly US) institutional shareholders, so a transfer to a non-EU sovereign entity is unlikely rather than imminent.
SOV-1.3Control over roadmap2. Through 'voice of the customer' public channels42/125SEAL-2mediumforeign_parent: roadmap set centrally by the US company; EU customers influence only via public 'voice of the customer' channels, no EU governance body -> SOV-1.3 opt2.
SOV-1.4Financial independence from non-EU capital1. Almost entirely relying on non-EU funding0/125SEAL-4highFunding is almost entirely US capital (IPO on NYSE, largest holder US-based Access Industries/Len Blavatnik); essentially no EU funding base.
SOV-1.5EU economic contribution2. Some31/125SEAL-4mediumPredominantly a US economic actor; EU contribution limited to leased data-centre presence in Amsterdam/Frankfurt and EU customer revenue, a minority of overall footprint.
SOV-1.6Participation in EU strategic programs1. No clear participation0/125SEAL-4mediumNo evident participation in EU strategic programs such as Gaia-X or IPCEI-CIS.
SOV-1.7Alignment with EU industrial strategies1. No evidence exists0/125SEAL-4mediumNo evidence of alignment with or action plan toward EU industrial/sovereignty strategies; positioning is global, NVIDIA-led AI factory rather than EU-aligned.
SOV-1.8Resilience to cut-off3. Can continue temporarily per contractual agreement63/125SEAL-2lowNot own_stack (foreign-controlled provider on leased colocation infra plus US chip vendors), but a standard IaaS/PaaS with documented data-export tooling and contractual terms under which the EU service could continue temporarily after a cut-off rather than shutting down immediately -> SOV-1.8 opt3 (seal 2), consistent with US commodity-IaaS peers.

SOV-2 · Legal & Jurisdictional Sovereignty 21.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-2.1Primary legal jurisdiction2. Mixed EU/non-EU84/167SEAL-1highEU customers contract under a GDPR DPA with SCCs/DPF while the provider and parent are US entities; primary jurisdiction is therefore mixed EU/non-EU rather than exclusively EU law -> SOV-2.1 opt2. (src: https://www.digitalocean.com/legal/data-processing-agreement)
SOV-2.2Extraterritorial laws exposure2. Mitigation clauses, exposure remains42/167SEAL-1highNo immunity (no SecNumCloud/EUCS-High, no EU trustee structure); SCC/DPA mitigation clauses exist but exposure to US extraterritorial law (CLOUD Act/FISA 702) remains -> SOV-2.2 opt2. (src: https://www.digitalocean.com/trust/schrems-ii-faq)
SOV-2.3Data access pathways for non-EU authorities2. Can compel access without notification, specific cases42/167SEAL-1highforeign_parent: as a US company DigitalOcean is subject to the CLOUD Act/FISA and can be compelled to produce data, in specific cases under gag orders preventing notification -> SOV-2.3 opt2 (seal 1, caps SEAL at 1). (src: https://www.digitalocean.com/trust/schrems-ii-faq)
SOV-2.4Export control restrictions2. Restrictions towards EU citizens or international orgs42/167SEAL-1lowSubject to US export-control/OFAC regimes that can restrict service to specific sanctioned EU citizens/orgs, but no restriction targets an EU Member State and EU revenue is not a >50% majority -> SOV-2.4 opt2.
SOV-2.5Origin of IP1. Entirely outside the EU0/167SEAL-4highCore platform IP developed and owned by the US company; IP originates entirely outside the EU.
SOV-2.6IP holder jurisdiction1. Non-EU law, single country0/167SEAL-3highIP held by the US parent under US (single-country) law -> SOV-2.6 opt1.

SOV-3 · Data & AI Sovereignty 45.0% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-3.1Customer control over encryption keys2. Primarily provider, not exclusively50/200SEAL-1mediumEncryption at rest is AES-256/LUKS with provider-managed keys; only object storage offers SSE-C, no platform-wide customer-managed KMS, so the provider can generally read data -> SOV-3.1 opt2.
SOV-3.2Transparent data flows & access logs3. Logs exist but not real-time / vendor-controlled100/200SEAL-2lowActivity/audit logs and a monitoring/insights portal exist but are vendor-controlled and not independently auditable in real time -> SOV-3.2 opt3.
SOV-3.3Secure deletion & proof of erasure3. Internal validation per policy, no proof100/200SEAL-1lowDeletion follows internal policy with destruction of storage on decommission, but no customer-facing cryptographic proof of erasure -> SOV-3.3 opt3 (policy-only).
SOV-3.4Data location strictly in EU/EEA4. EU by default, tightly controlled exceptions150/200SEAL-1mediumNo eu_exclusive sovereign offer, but customer data uploaded to a chosen region (e.g. FRA1 Frankfurt, AMS3 Amsterdam) remains in that region: EU-by-default with tightly controlled exceptions rather than a contractual no-third-country guarantee -> SOV-3.4 opt4 (seal 1). (src: https://www.digitalocean.com/blog/digitalocean-bare-metal-gpus-eu-data-center)
SOV-3.5AI services sovereignty2. Mostly non-EU: licensed AI, chip dependency50/200SEAL-2highGradient/GenAI relies on licensed third-party models (OpenAI, Anthropic, Llama, NVIDIA Nemotron) on US-designed NVIDIA/AMD accelerators; mostly non-EU with chip dependency -> SOV-3.5 opt2.

SOV-4 · Operational Sovereignty 25.1% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-4.1Portability & interoperability3. Standard documented data export methods84/167SEAL-4mediumStandards-based, documented APIs and data export (S3-compatible Spaces, standard snapshots/images) enable portability -> SOV-4.1 opt3.
SOV-4.2Ability to operate without foreign dependencies1. Critical ops delivered by non-EU teams0/167SEAL-1mediumNo eu_ops: critical platform engineering and operations run by globally distributed, predominantly US-based teams; the EU cannot operate the stack independently -> SOV-4.2 opt1.
SOV-4.3Skill availability in the EU2. Mixed, majority outside EU42/167SEAL-1lowEngineering/operations talent is a global team with the majority outside the EU -> SOV-4.3 opt2.
SOV-4.4Support channels2. Mixed, majority outside EU42/167SEAL-2lowSupport is global (follow-the-sun) with the majority of staff outside the EU -> SOV-4.4 opt2.
SOV-4.5Documentation & knowledge transfer2. EU optional, not enforced42/167SEAL-2lowDocumentation and knowledge repositories are global English-language resources; EU residency is optional and not enforced -> SOV-4.5 opt2 (seal 2), consistent with US commodity-IaaS peers.
SOV-4.6Subcontractor & supplier jurisdiction2. Service would stop with delay42/167SEAL-2lowHeavy reliance on non-EU subcontractors (US colocation providers, US chip vendors); loss of these would stop the service with only a delay for customers -> SOV-4.6 opt2.

SOV-5 · Supply Chain Sovereignty 21.6% · SEAL-1 · weight 10%

IDFactorValueScoreSEALConf.Justification
SOV-5.1Origin of components (physical parts)2. Partial disclosure36/143SEAL-1lowPhysical components (servers, NVIDIA/AMD GPUs) are foreign-origin with only partial public disclosure of provenance -> SOV-5.1 opt2.
SOV-5.2Manufacturing location2. Foreign origin, partial disclosure36/143SEAL-1lowHardware manufactured by foreign (US/Asia) OEMs and chip makers with only partial disclosure; not built by EU teams -> SOV-5.2 opt2.
SOV-5.3Embedded code/firmware provenance2. Partial disclosure36/143SEAL-4lowFirmware/embedded code provenance (BIOS, GPU firmware) is foreign and only partially disclosed.
SOV-5.4Origin of software2. Foreign origin, partial disclosure36/143SEAL-2mediumforeign_core: core platform software is the US company's proprietary stack of foreign origin with partial disclosure (some open-source tooling published), not maintained by EU teams -> SOV-5.4 opt2 (seal 2), consistent with US commodity-IaaS peers.
SOV-5.5Software build/release jurisdiction1. Non-EU control & execution0/143SEAL-1mediumSoftware build and release are controlled and executed by the US company outside the EU -> SOV-5.5 opt1.
SOV-5.6Single point of dependency2. Mostly non-EU, undocumented36/143SEAL-1mediumCritical services depend on non-EU vendors (US colocation/data-centre operators, US/Asia chip suppliers, US AI model providers) with little documentation of EU alternatives -> SOV-5.6 opt2.
SOV-5.7Supply chain transparency2. Some suppliers auditable36/143SEAL-1lowSome suppliers/data-centre partners are disclosed and SOC-2-audited, but the full supply chain is not customer-auditable -> SOV-5.7 opt2.

SOV-6 · Technology Sovereignty 45.0% · SEAL-2 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-6.1Interoperability & open interfaces4. Standards-based and broadly compatible150/200SEAL-3mediumInterfaces are largely standards-based and broadly compatible (S3-compatible object storage, standard Linux/Kubernetes/Postgres, open REST APIs) -> SOV-6.1 opt4.
SOV-6.2Open standards compliance3. Partial core adoption100/200SEAL-2mediumOpen standards adopted for core services (DOKS/Kubernetes, S3 API, standard OS images and databases) but not via a comprehensive published policy across all services -> SOV-6.2 opt3.
SOV-6.3Open source availability2. Source available for review, strict rights50/200SEAL-2mediumforeign_core: the managed platform is closed-source/vendor-controlled; some open-source tooling published but the core service is not open -> SOV-6.3 opt2 (seal 2).
SOV-6.4Service architecture transparency3. Some public insight100/200SEAL-3lowSubstantial public documentation, tutorials and shared-responsibility/architecture material provide some public insight -> SOV-6.4 opt3.
SOV-6.5HPC sovereignty2. EU-hosted, foreign stack50/200SEAL-3mediumGPU/HPC capacity is offered in EU regions (Amsterdam bare-metal GPUs) but runs on imported NVIDIA/AMD hardware and stack: EU-hosted on a foreign stack rather than imported black-box with no EU footprint -> SOV-6.5 opt2 (seal 3), consistent with US commodity-IaaS peers. (src: https://www.digitalocean.com/blog/digitalocean-bare-metal-gpus-eu-data-center)

SOV-7 · Security & Compliance Sovereignty 39.6% · SEAL-1 · weight 15%

IDFactorValueScoreSEALConf.Justification
SOV-7.1Security certification (EAL)3. EAL272/143SEAL-2mediumNo SecNumCloud/EUCS-High/Common Criteria EAL, but holds SOC 2/3 Type II (Schellman) plus ISO 27001 and CSA STAR L1; per the key's cert map ISO 27001 + SOC 2 -> EAL2-equivalent -> SOV-7.1 opt3 (seal 2). (src: https://www.digitalocean.com/trust/certification-reports)
SOV-7.2EU regulatory compliance (GDPR/NIS2/DORA)3. Moderate compliance72/143SEAL-4mediumGDPR-compliant with DPA/SCCs, SOC 2/3 Type II, ISO 27001, CSA STAR L1, stated DORA eligibility, but no EUCS/SecNumCloud; moderate compliance -> SOV-7.2 opt3.
SOV-7.3EU-based SOC & incident handling2. Hybrid EU/non-EU36/143SEAL-1lowSecurity operations and incident response run by global teams in a hybrid EU/non-EU arrangement, not EU-exclusive -> SOV-7.3 opt2.
SOV-7.4Control over security monitoring/logging3. Basic monitoring portal72/143SEAL-1lowCustomers get a monitoring/insights portal with activity logs and periodic reports, but the provider retains primary control of security logging; no immutable EU-resident customer-controlled logs -> SOV-7.4 opt3 (basic monitoring portal), consistent with US commodity-IaaS peers.
SOV-7.5Disclosure of incidents3. Moderate (GDPR/NIS2-aligned)72/143SEAL-2mediumIncident disclosure is moderate and GDPR/breach-notification aligned via the DPA, but not full real-time CSIRT sharing -> SOV-7.5 opt3.
SOV-7.6Maintenance autonomy2. Limited autonomy (vendor schedules)36/143SEAL-1lowAs a managed multi-tenant platform, maintenance windows and patching are vendor-scheduled; customers have limited autonomy over the underlying platform -> SOV-7.6 opt2.
SOV-7.7Auditability2. Limited independent access36/143SEAL-1lowNo audit_rights: independent assurance is via third-party SOC 2/3 reports on request; customers cannot perform unrestricted independent audits of the infrastructure -> SOV-7.7 opt2.

SOV-8 · Environmental Sustainability 43.8% · SEAL-1 · weight 5%

IDFactorValueScoreSEALConf.Justification
SOV-8.1Energy efficiency (PUE)3. PUE < 1.5 + roadmap125/250SEAL-4lowDigitalOcean reports its data centres average a PUE of ~1.15 and invests in efficient hardware and renewable energy: PUE well under 1.5 with an efficiency roadmap -> SOV-8.1 opt3. (src: https://investors.digitalocean.com/esg/environmental/default.aspx)
SOV-8.2Hardware reuse & recycling3. Documented program125/250SEAL-3lowHardware lifecycle is handled through DigitalOcean's colocation partners with a documented circular/efficiency program (efficient hardware reuse and responsible decommissioning) reflected in its ESG disclosures -> SOV-8.2 opt3 (documented program), consistent with US commodity-IaaS peers. (src: https://investors.digitalocean.com/esg/environmental/default.aspx)
SOV-8.3Environmental impact reporting2. Basic reporting63/250SEAL-1lowPublishes ESG/environmental disclosures on its investor site but without detailed carbon figures under a formal annual environmental report with reduction targets -> SOV-8.3 opt2. (src: https://investors.digitalocean.com/esg/environmental/default.aspx)
SOV-8.4Energy supplies3. Mix of EU and non-EU supplies125/250SEAL-4lowEnergy drawn from a mix of EU and non-EU colocation facilities; DigitalOcean does not control or fully disclose per-site energy mix, implying a global mix of supplies.